Policy
Verification Policy
Verification decides what we may show you about a domain. It does not decide what we may do to it — and conflating the two is the mistake this document exists to prevent.
Last reviewed 1 August 2026. Where this document changes materially, the revision date changes with it.
01
Why verification exists
A public snapshot shows what any member of the public could establish about a website. That is a defensible amount to show an anonymous visitor, and it is deliberately less than we observed.
Verification changes the audience. Once we have reasonable confidence that the person asking has a genuine relationship with the domain, more of what was observed can be shown — affected addresses in fuller form, organisational exposure detail, and the evidence behind findings that would otherwise be summarised.
It is an access-control mechanism for information, not a permission-granting mechanism for activity. Nothing about what IXSEO does changes after verification. Every check remains passive.
02
Approved methods
Administrative email at the domain. A code sent to an approved administrative address at the domain itself. Establishes access to that mailbox. Convenient, and the weakest of the methods listed here, since mailbox access is frequently broader than domain control.
DNS TXT record. A supplied token published as a TXT record on the domain. Establishes control of the DNS zone, which is a considerably stronger signal.
HTML verification file. A supplied file placed at a given path on the website. Establishes the ability to publish to the web root.
Meta tag. A supplied token in a meta element on the home page. Equivalent to the file method, and easier on platforms that restrict file uploads.
Google Search Console. Confirmation of an existing verified property. Establishes that the domain is already verified with a third party applying its own checks.
Cloudflare or Microsoft 365. Confirmation through an existing administrative relationship with a provider that has already established control.
Written agency authorisation. A written instruction from the domain owner authorising an agency or consultant to act on their behalf for this purpose. Used where the person doing the work legitimately does not hold direct control.
03
What verification unlocks
- expanded passive findings across selected modules
- affected addresses stated in fuller form
- organisational email exposure findings beyond counts and masked samples
- detailed DNS and infrastructure review, including specific configuration observations
- evidence appropriate for an authorised recipient
- a downloadable executive report
- eligibility for paid professional assessment options
Every item on that list is a change to what is displayed. None of them is a change to what is performed.
04
What verification does not authorise
Domain verification does not automatically authorise active infrastructure testing.
Specifically, a verified domain does not permit port scanning, service enumeration, vulnerability testing, authentication attempts, form submission or any other active technique. Those require a separate signed authorisation which must establish:
- the legal entity commissioning the work
- the authorising individual, their role, and their authority to grant it
- the exact domains and address ranges in scope
- systems explicitly excluded from scope
- the agreed testing window
- rate limits and rules of engagement
- an emergency contact and defined stop conditions
A person with access to an administrative mailbox is frequently not the person with authority to commission testing of the organisation’s infrastructure. Treating a verification code as consent to that would be indefensible, and we do not do it.
05
How verification records are handled
A verification record holds the domain, the method used, the status, who requested it, when it was confirmed, when it expires and a reference to the evidence. It does not hold the contents of a mailbox, credentials, or anything beyond what was needed to confirm the check.
Verifications expire. A domain changes hands, an employee leaves, an agency relationship ends — a verification confirmed two years ago is not evidence about today. Re-verification is required after expiry, and any verification may be revoked on request from someone demonstrating control.
Evidence is retained only for as long as it serves an operational need, as described in the data retention policy.
06
Disputed or changed control
If you believe someone has verified a domain they should not have, contact us through the contact page. We will suspend the verification while it is examined. Where control of a domain is genuinely disputed between parties, we will not adjudicate: the verification stays suspended and no expanded findings are shown to anyone until the dispute is resolved between them.
Related documents
Questions about this document can be raised through the contact page. Nothing here is intended to restrict rights you hold under applicable law.